Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 324

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Analysis: Iran war energy shock hits the U.S. economy as gas and diesel prices climb
the emotionally soothing terrarium channel
China's Geely to make EVs at Ford plant in Spain under new joint venture
Brent crude tops $100 a barrel. How the next stop could be $120
Dow tumbles 500 points as Brent crude tops $100, Alphabet and Tesla drop: Live updates
X-Men '97: Danger.Exe
Tesla gets price target cuts from analysts on earnings miss. What they're saying
Silo: Whatever You Do, Don't Go Home Show Only
Ann Droid: Season 1
Star Trek: Strange New Worlds: Valles Marineris